CVE-2024-40000 to CVE-2024-40999
71 CVEs with public proof-of-concept exploits.
- CVE-2024-400351 PoCidccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/userLevel_deal.php?mudi=add.
- CVE-2024-400361 PoCidccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via…
- CVE-2024-400381 PoCidccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/userScore_deal.php?mudi=rev
- CVE-2024-400943 PoCsGraphQL Java (aka graphql-java) before 21.5 does not properly consider ExecutableNormalizedFields (ENFs) as part of preventing denial of…
- CVE-2024-401105 PoCsSourcecodester Poultry Farm Management System v1.0 contains an Unauthenticated Remote Code Execution (RCE) vulnerability via the…
- CVE-2024-401111 PoCA persistent (stored) cross-site scripting (XSS) vulnerability has been identified in Automad 2.0.0-alpha.4. This vulnerability enables an…
- CVE-2024-401121 PoCA Local File Inclusion (LFI) vulnerability exists in Sitecom WLX-2006 Wall Mount Range Extender N300 v1.5 and before, which allows an…
- CVE-2024-401141 PoCA Cross Site Scripting (XSS) vulnerability in Sitecom WLX-2006 Wall Mount Range Extender N300 v1.5 and before allows an attacker to…
- CVE-2024-401192 PoCsNepstech Wifi Router xpon (terminal) model NTPL-Xpon1GFEVN v.1.0 Firmware V2.0.1 contains a Cross-Site Request Forgery (CSRF)…
- CVE-2024-401201 PoCseaweedfs v3.68 was discovered to contain a SQL injection vulnerability via the component /abstract_sql/abstract_sql_store.go.
- CVE-2024-401241 PoCPydio Core <= 8.2.5 is vulnerable to Cross Site Scripting (XSS) via the New URL Bookmark feature.
- CVE-2024-401251 PoCAn arbitrary file upload vulnerability in the Media Manager function of Closed-Loop Technology CLESS Server v4.5.2 allows attackers to…
- CVE-2024-403181 PoCAn arbitrary file upload vulnerability in Webkul Qloapps v1.6.0.0 allows attackers to execute arbitrary code via uploading a crafted file.
- CVE-2024-403241 PoCA CRLF injection vulnerability in E-Staff v5.1 allows attackers to insert Carriage Return (CR) and Line Feed (LF) characters into input…
- CVE-2024-403281 PoCidccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via…
- CVE-2024-403291 PoCidccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/softBak_deal.php?mudi=backup
- CVE-2024-403311 PoCidccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/dbBakMySQL_deal.php?mudi=backup
- CVE-2024-403331 PoCidccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/softBak_deal.php?mudi=del&dataID=2
- CVE-2024-403361 PoCidccms v1.35 is vulnerable to Cross Site Scripting (XSS) within the 'Image Advertising Management.'
- CVE-2024-403484 PoCsAn issue in the component /api/swaggerui/static of Bazaar v1.4.3 allows unauthenticated attackers to execute a directory traversal.
- CVE-2024-403921 PoCSourceCodester Pharmacy/Medical Store Point of Sale System Using PHP/MySQL and Bootstrap Framework with Source Code 1.0 was discovered to…
- CVE-2024-403931 PoCOnline Clinic Management System In PHP With Free Source code v1.0 was discovered to contain a SQL injection vulnerability via the user…
- CVE-2024-403941 PoCSimple Library Management System Project Using PHP/MySQL v1.0 was discovered to contain an arbitrary file upload vulnerability via the…
- CVE-2024-404001 PoCAn arbitrary file upload vulnerability in the image upload function of Automad v2.0.0 allows attackers to execute arbitrary code via a…
- CVE-2024-404021 PoCA SQL injection vulnerability was found in 'ajax.php' of Sourcecodester Simple Library Management System 1.0. This vulnerability stems…
- CVE-2024-404225 PoCsThe snapshot_path parameter in the /api/get-browser-snapshot endpoint in stitionai devika v1 is susceptible to a path traversal attack. An…
- CVE-2024-404271 PoCStack Buffer Overflow in PX4-Autopilot v1.14.3, which allows attackers to execute commands to exploit this vulnerability and cause the…
- CVE-2024-404312 PoCsA lack of input validation in Realtek SD card reader driver before 10.0.26100.21374 through the implementation of the…
- CVE-2024-404331 PoCInsecure Permissions vulnerability in Tencent wechat v.8.0.37 allows an attacker to escalate privileges via the web-view component.
- CVE-2024-404431 PoCSQL Injection vulnerability in Simple Laboratory Management System using PHP and MySQL v.1.0 allows a remote attacker to cause a denial of…
- CVE-2024-404451 PoCA directory traversal vulnerability in forkosh Mime TeX before version 1.77 allows attackers on Windows systems to read or append…
- CVE-2024-404461 PoCAn issue in forkosh Mime Tex before v.1.77 allows an attacker to execute arbitrary code via a crafted script
- CVE-2024-404531 PoCsquirrellyjs squirrelly v9.0.0 and fixed in v.9.0.1 was discovered to contain a code injection vulnerability via the component…
- CVE-2024-404571 PoCNo-IP Dynamic Update Client (DUC) v3.x uses cleartext credentials that may occur on a command line or in a file. NOTE: the vendor's…
- CVE-2024-404921 PoCCross Site Scripting vulnerability in Heartbeat Chat v.15.2.1 allows a remote attacker to execute arbitrary code via the setname function.
- CVE-2024-404981 PoCSQL Injection vulnerability in PuneethReddyHC Online Shopping sysstem advanced v.1.0 allows an attacker to execute arbitrary code via the…
- CVE-2024-405021 PoCSQL injection vulnerability in Hospital Management System Project in ASP.Net MVC 1 allows aremote attacker to execute arbitrary code via…
- CVE-2024-405061 PoCCross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via the…
- CVE-2024-405071 PoCCross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via the…
- CVE-2024-405081 PoCCross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via the…
- CVE-2024-405091 PoCCross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via the…
- CVE-2024-405101 PoCCross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via the…
- CVE-2024-405111 PoCCross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via the…
- CVE-2024-405121 PoCCross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via the…
- CVE-2024-405391 PoCmy-springsecurity-plus before v2024.07.03 was discovered to contain a SQL injection vulnerability via the dataScope parameter at /api/user.
- CVE-2024-405401 PoCmy-springsecurity-plus before v2024.07.03 was discovered to contain a SQL injection vulnerability via the dataScope parameter at /api/dept.
- CVE-2024-405411 PoCmy-springsecurity-plus before v2024.07.03 was discovered to contain a SQL injection vulnerability via the dataScope parameter at…
- CVE-2024-405421 PoCmy-springsecurity-plus before v2024.07.03 was discovered to contain a SQL injection vulnerability via the dataScope parameter at…
- CVE-2024-405431 PoCPublicCMS v4.0.202302.e was discovered to contain a Server-Side Request Forgery (SSRF) via the component /admin/ueditor?action=catchimage.
- CVE-2024-405481 PoCAn arbitrary file upload vulnerability in the component /admin/cmsTemplate/save of PublicCMS v4.0.202302.e allows attackers to execute…
- CVE-2024-405701 PoCSQL Injection vulnerability in SeaCMS v.12.9 allows a remote attacker to obtain sensitive information via the admin_datarelate.php…
- CVE-2024-405761 PoCCross Site Scripting vulnerability in Best House Rental Management System 1.0 allows a remote attacker to execute arbitrary code via the…
- CVE-2024-405821 PoCPentaminds CuroVMS v2.0.1 was discovered to contain exposed sensitive information.
- CVE-2024-405831 PoCPentaminds CuroVMS v2.0.1 was discovered to contain exposed credentials.
- CVE-2024-405861 PoCAn Improper Access Control vulnerability [CWE-284] in FortiClient Windows version 7.4.0, version 7.2.6 and below, version 7.0.13 and below…
- CVE-2024-406171 PoCPath traversal vulnerability exists in FUJITSU Network Edgiot GW1500 (M2M-GW for FENICS). If a remote authenticated attacker with User…
- CVE-2024-406261 PoCStored Cross-site Scripting (XSS) vulnerability in Outline editor
- CVE-2024-406271 PoCOpaMiddleware does not filter HTTP OPTIONS requests
- CVE-2024-406342 PoCsArgo CD Unauthenticated Denial of Service (DoS) Vulnerability via /api/webhook Endpoint
- CVE-2024-406351 PoCcontainerd has an integer overflow in User ID handling
- CVE-2024-406431 PoCJoplin has a parsing error leading to Cross-site Scripting (XSS)
- CVE-2024-406441 PoCgitoxide's gix-path can use a fake program files location
- CVE-2024-406761 PoCIn checkKeyIntent of AccountManagerService.java, there is a possible way to bypass intent security check and install an unknown app due to…
- CVE-2024-407114 PoCsKEVA deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code execution (RCE).
- CVE-2024-407252 PoCsApache HTTP Server: source code disclosure with handlers configured via AddType
- CVE-2024-407671 PoCIn OpenStack Nova before 27.4.1, 28 before 28.2.1, and 29 before 29.1.1, by supplying a raw format image that is actually a crafted QCOW2…
- CVE-2024-408151 PoCA race condition was addressed with additional validation. This issue is fixed in macOS Ventura 13.6.8, iOS 17.6 and iPadOS 17.6, watchOS…
- CVE-2024-408911 PoCKEV**UNSUPPORTED WHEN ASSIGNED**A post-authentication command injection vulnerability in the management commands of the legacy DSL CPE Zyxel…
- CVE-2024-408922 PoCsFirewalla BTLE Weak Credentials
- CVE-2024-408932 PoCsFirewalla BTLE Authenticated Command Injection
- CVE-2024-408983 PoCsApache HTTP Server: SSRF with mod_rewrite in server/vhost context on Windows